Skip to content

Commit 68ca477

Browse files
authored
Switch to pull non-secret values from env (#376)
1 parent ca7b1ff commit 68ca477

File tree

3 files changed

+17
-17
lines changed

3 files changed

+17
-17
lines changed

.github/workflows/cleanup.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -18,14 +18,14 @@ jobs:
1818

1919
- uses: 'google-github-actions/auth@main'
2020
with:
21-
workload_identity_provider: '${{ secrets.WIF_PROVIDER_NAME }}'
22-
service_account: '${{ secrets.SERVICE_ACCOUNT_EMAIL }}'
21+
workload_identity_provider: '${{ vars.WIF_PROVIDER_NAME }}'
22+
service_account: '${{ vars.SERVICE_ACCOUNT_EMAIL }}'
2323

2424
- uses: 'google-github-actions/setup-gcloud@main'
2525

2626
- name: Delete services
2727
run: |-
28-
gcloud config set core/project "${{ secrets.PROJECT_ID }}"
28+
gcloud config set core/project "${{ vars.PROJECT_ID }}"
2929
gcloud config set functions/region "us-central1"
3030
3131
# List and delete all functions that were deployed 30 minutes ago or

.github/workflows/integration.yml

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -32,8 +32,8 @@ jobs:
3232

3333
- uses: 'google-github-actions/auth@main'
3434
with:
35-
workload_identity_provider: '${{ secrets.WIF_PROVIDER_NAME }}'
36-
service_account: '${{ secrets.SERVICE_ACCOUNT_EMAIL }}'
35+
workload_identity_provider: '${{ vars.WIF_PROVIDER_NAME }}'
36+
service_account: '${{ vars.SERVICE_ACCOUNT_EMAIL }}'
3737

3838
- id: 'deploy'
3939
uses: './'
@@ -62,8 +62,8 @@ jobs:
6262

6363
- uses: 'google-github-actions/auth@main'
6464
with:
65-
workload_identity_provider: '${{ secrets.WIF_PROVIDER_NAME }}'
66-
service_account: '${{ secrets.SERVICE_ACCOUNT_EMAIL }}'
65+
workload_identity_provider: '${{ vars.WIF_PROVIDER_NAME }}'
66+
service_account: '${{ vars.SERVICE_ACCOUNT_EMAIL }}'
6767

6868
- id: 'deploy'
6969
uses: './'
@@ -73,16 +73,16 @@ jobs:
7373
entry_point: 'helloWorld'
7474
source_dir: './tests/test-node-func/'
7575
event_trigger_type: 'providers/cloud.pubsub/eventTypes/topic.publish'
76-
event_trigger_resource: '${{ secrets.PUBSUB_TOPIC_NAME }}'
76+
event_trigger_resource: '${{ vars.PUBSUB_TOPIC_NAME }}'
7777
event_trigger_retry: true
7878
env_vars_file: './tests/env-var-files/test.good.yaml'
7979
build_environment_variables: 'FOO=bar, ZIP=zap'
8080
build_environment_variables_file: './tests/env-var-files/test.good.yaml'
8181
secret_environment_variables: |-
82-
FOO=${{ secrets.SECRET_VERSION_NAME }}
83-
BAR=${{ secrets.SECRET_NAME }}
84-
secret_volumes: '/etc/secrets/foo=${{ secrets.SECRET_VERSION_NAME }}'
85-
service_account_email: '${{ secrets.SERVICE_ACCOUNT_EMAIL }}'
82+
FOO=${{ vars.SECRET_VERSION_NAME }}
83+
BAR=${{ vars.SECRET_NAME }}
84+
secret_volumes: '/etc/secrets/foo=${{ vars.SECRET_VERSION_NAME }}'
85+
service_account_email: '${{ vars.SERVICE_ACCOUNT_EMAIL }}'
8686
min_instances: 2
8787
max_instances: 5
8888
timeout: 300

.github/workflows/unit.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -47,12 +47,12 @@ jobs:
4747
- uses: 'google-github-actions/auth@main'
4848
if: ${{ github.event_name == 'push' || github.repository == github.event.pull_request.head.repo.full_name && github.actor != 'dependabot[bot]' }}
4949
with:
50-
workload_identity_provider: '${{ secrets.WIF_PROVIDER_NAME }}'
51-
service_account: '${{ secrets.SERVICE_ACCOUNT_EMAIL }}'
50+
workload_identity_provider: '${{ vars.WIF_PROVIDER_NAME }}'
51+
service_account: '${{ vars.SERVICE_ACCOUNT_EMAIL }}'
5252

5353
- name: 'npm test'
5454
env:
55-
TEST_PROJECT_ID: '${{ secrets.PROJECT_ID }}'
56-
TEST_SERVICE_ACCOUNT_EMAIL: '${{ secrets.SERVICE_ACCOUNT_EMAIL }}'
57-
TEST_SECRET_VERSION_NAME: '${{ secrets.SECRET_VERSION_NAME }}'
55+
TEST_PROJECT_ID: '${{ vars.PROJECT_ID }}'
56+
TEST_SERVICE_ACCOUNT_EMAIL: '${{ vars.SERVICE_ACCOUNT_EMAIL }}'
57+
TEST_SECRET_VERSION_NAME: '${{ vars.SECRET_VERSION_NAME }}'
5858
run: 'npm run test'

0 commit comments

Comments
 (0)